Missing User Warnings
Medium
- Confidence
- 86% confidence
- Finding
- The skill explicitly instructs use of a generic proxy request mechanism to send arbitrary requests to an external API, but it does not warn that user-supplied data may be transmitted off-platform. In an agent setting, this increases the chance of unintended data exfiltration, especially if the agent forwards sensitive prompts, records, or identifiers through the proxy without clear user awareness or confirmation.
